Solved Let's Encrypt cert renewal : issuer not in server's trust store

Status
Not open for further replies.

mls.nicolas

Gold Partner
Advanced Certified
Joined
Apr 22, 2022
Messages
33
Reaction score
18
Hello all,

This night, one of my debian 3CX server renewed its Let's Encrypt certificate automatically, as usual. But it came with a new issuer this time.
  • previously : CN=R13,O=Let's Encrypt,C=US
  • since today : CN=YR1,O=Let's Encrypt,C=US

It appears that the new CA/chain is not present in the server trust store. I guess this should normally be handled by the certificate renewal tool embedded in 3CX or by debian updates.

Therefore, the 3CX server cannot access itself.(FQDN and IP address obfuscated) :
root@my3cxserver:~# wget https://my3cxserver.3cx.ch
--2026-05-29 10:23:33-- https://my3cxserver.3cx.ch/
Resolving my3cxserver.3cx.ch (my3cxserver.3cx.ch)... 192.0.2.10
Connecting to my3cxserver.3cx.ch (my3cxserver.3cx.ch)|192.0.2.10|:443... connected.
ERROR: The certificate of ‘my3cxserver.3cx.ch’ is not trusted.
ERROR: The certificate of ‘my3cxserver.3cx.ch’ doesn't have a known issuer.

While browsers and softphones are not having any issue connecting, as the cert issuer is in their trust store, it might be good to still investigate why the server trust store was not updated with the latest LE CA.

Thanks
 
Last edited:
  • Like
Reactions: WifxMain
We had one client PBX renew cert this morning and are seeing the same thing.
 
Comparing server renewed today, 5/29.26 to server not yet renewed, here is ssllabs response
1780060148850.png
 
  • Like
Reactions: mls.nicolas
Same issue with customers !
Should we open a ticket ?
 
  • Like
Reactions: mls.nicolas
  • Like
Reactions: KyriacosS_3CX
Thanks @ChrisC_3CX, renewing the certificate fixed it indeed.
 
@ChrisC_3CX we just ran into this issue as well and running the manual cert renewal process did resolve it. My question, was this a temporary issue that has been resolved? Or, will we need to manually renew each cert after the next time it goes through the automatic renewal process?
 
@pmterp Certainly check, but I had 4 other systems renew SSL yesterday and today. They did not seem to have the issue, only the ones that renewed of Friday.
 
@pmterp We expect all new cert generations including renewals to be fine from here on out.
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK